谷歌浏览器插件
订阅小程序
在清言上使用

Security Identifier Randomization: A Method To Prevent Kernel Privilege-Escalation Attacks

2016 30th International Conference on Advanced Information Networking and Applications Workshops (WAINA)(2016)

引用 3|浏览12
暂无评分
摘要
Privilege escalation attack is one of the serious threats to Linux. So the protection of the root user is an important requirement for Linux systems and SELinux has tackled this issue in some degree. But by exploiting kernel privilege-escalation vulnerabilities, the attackers can tamper security identifiers allocated for the process's security contexts, which are the foundation of SELinux enforcing access control. So we propose security identifier randomization method, which can increase the difficulty of kernel privilege-escalation attacks. This method is application transparent and its influence on overall system performance is within 1%.
更多
查看译文
关键词
SELinux,privilege escalation,vulnerability exploitation
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要